Sample audits

Nacodex audits, published in full, finding by finding.

Open-source projects and developer documentation, each audit pinned to one public commit or one dated copy of the pages. Every finding is shown with the severity it kept after review, the location it points to, and the report's own evidence and suggested fix.

How to read these results

The severities shown are the ones that survived review, not the first automated rating. Each finding was read again against the audited code or pages; findings that held up keep or lower their rating, usually because the behaviour is documented, needs unusual configuration, fails loudly, or affects only examples or CI. Findings shown wrong on review, or repeating another finding, are listed separately as excluded. Where a finding was not individually re-checked, its page says so and shows the first rating.

Verdict rule: Fail if a High finding remains after review, otherwise Pass with notes.

How each audit ran: the first eight as an API run on the Nacodex server; the next eight in a cloud session; the October 2026 workstation audits as a local run on our workstation; the earlier documentation audits are our May to September 2026 reports, published as delivered, with their findings re-checked against the live pages on 11 October 2026. All are full audits at Standard review depth.

21
audits reviewed finding by finding
1001
findings in their reports
567 → 95
first rated Medium or High, and after review
6
High after review
10
excluded on review
3
audits with a Fail verdict

All audits

GroupAuditedDateHow it ranHighMediumLowInfoExcludedVerdict
Open-source projects, first eight · API run on the Nacodex server
Aauth0/node-jsonwebtoken11 October 2026API run on the Nacodex server00330Pass with notes
AJakeWharton/timber11 October 2026API run on the Nacodex server01890Pass with notes
Ahelmetjs/helmet11 October 2026API run on the Nacodex server00120Pass with notes
Aexpressjs/session11 October 2026API run on the Nacodex server01720Pass with notes
Apaulmillr/noble-ed2551911 October 2026API run on the Nacodex server00060Pass with notes
Aandroid/architecture-samples11 October 2026API run on the Nacodex server0215120Pass with notes
Aanza-xyz/wallet-adapter11 October 2026API run on the Nacodex server021540Pass with notes
Asolana-foundation/solana-web3.js11 October 2026API run on the Nacodex server041362Pass with notes
Open-source projects and documentation, eight more · cloud session
BJupiter developer docs: pages changed or added since May11 October 2026cloud session045622Pass with notes
BHelius docs: pages changed or added since May11 October 2026cloud session098110Pass with notes
Bhorizontalsystems/unstoppable-wallet-android11 October 2026cloud session036510Pass with notes
Bsolana-foundation/program-examples11 October 2026cloud session264330Fail
Bsendaifun/solana-agent-kit11 October 2026cloud session32511002Fail
Bandroid/nowinandroid11 October 2026cloud session039150Pass with notes
BAnchor (otter-sec/anchor)11 October 2026cloud session033510Pass with notes
Btrustwallet/wallet-core11 October 2026cloud session064610Pass with notes
Workstation audits, October 2026 · local run on our workstation
CSolana Mobile developer documentation11 October 2026local run on our workstation026681Pass with notes
CSolana Mobile SDKs: mobile-wallet-adapter and seed-vault-sdk11 October 2026local run on our workstation18137160Fail
CORE: regolith-labs/ore, entropy and ore-stake11 October 2026local run on our workstation034602Pass with notes
CTensor developer documentation11 October 2026local run on our workstation012401Pass with notes
Cregolith-labs/steel11 October 2026local run on our workstation062400Pass with notes
Earlier documentation audits · earlier documentation audit
Severities as published in our original report; these findings were not re-reviewed by hand the way the sample audits were. Counts below are as first rated.
DJupiter developer documentationMay 2026earlier documentation audit79500as first rated; not re-reviewed
DHelius API documentationMay 2026earlier documentation audit216300as first rated; not re-reviewed
DHelius Gatekeeper documentationJune 2026earlier documentation audit27300as first rated; not re-reviewed
DMagic Eden developer documentationMay 2026earlier documentation audit97500as first rated; not re-reviewed
DTensor developer documentationMay 2026earlier documentation audit711300as first rated; not re-reviewed
DSolana Mobile documentation and SDKsJune 2026earlier documentation audit21252562as first rated; not re-reviewed
DSolana Mobile stack, third auditSeptember 2026earlier documentation audit276054120as first rated; not re-reviewed
Total, reviewed audits6898049210

Counts after review for groups A to C. Group D: as first rated in our original reports, not re-reviewed by hand and not included in the totals (Critical counted with High; Advisory with Info); their current status is in the re-check table below.

Documentation re-checks

Earlier this year we audited the developer documentation of five Solana ecosystem services: wrong code samples, dead links, contradictions between pages. On 11 October 2026 we fetched every cited page again and checked each finding against the current text. Each audit page shows the status of every finding.

DocumentationFirst auditFindingsFixedPartly fixedUnchangedCould not check
Tensor documentationMay 20262100201
Helius API documentationMay 20262122152
Helius Gatekeeper documentationJune 2026121380
Jupiter documentationMay 20262152131
Magic Eden documentationMay 20262100021

"Could not check": the page or the finding could not be compared. Magic Eden's documentation site now blocks automated access, so none of its findings could be re-checked. Tensor: 85 of its 90 pages are unchanged since May; the other 5 differ only in formatting.

Fixed since our audit: Jupiter
Every page pointed readers and AI agents to the retired host

The page banner and the sitemap used dev.jup.ag. Both now use developers.jup.ag.

The plans page billed endpoints that were being retired

The plans page listed seven Ultra endpoints as billable. It no longer does, and the Ultra pages now say they are no longer actively maintained.

API key instructions pointed to the old portal

All 91 API specifications now point to developers.jup.ag/portal.

The sitemap was stale and on the old host

It is now on the current host, last updated 7 October 2026.

A breaking change was still announced as upcoming after its date

The 14 May 2026 change is now written as enforced.

Fixed since our audit: Helius
Eight internal links in the Gatekeeper docs were broken

They were missing the /docs/ prefix; all eight are now correct, in English and Chinese.

The Enhanced Transactions API had no standalone specification

It is now published at helius.dev/openapi/enhanced-api.json and listed in the API catalog.

Two Chinese pages returned "not found"

Both are now served.

Solana Mobile

In June 2026 we audited the Solana Mobile developer documentation and SDKs and shared the full report with Solana Mobile. In the months that followed, ten of the issues it identified were corrected on the very pages it cited (eight in full, two in part), in the public commits listed below. We did not receive a reply, and the changes do not reference the report. We publish the complete June findings here, together with a fresh audit of the current documentation, so readers can follow what has changed and what remains open.

Public commits to the Solana Mobile documentation that corrected the cited pages:

All ten corrections were still in place on 11 October 2026. We do not claim that our report caused them.

The complete June 2026 findings · our September 2026 third audit · the fresh audit of the current documentation (October 2026)

About these samples

How they were made
  • Public code only, each project pinned to the commit named on its page; documentation audits use a dated copy of the published pages
  • Full audits at Standard review depth; the route of each audit (API run on the Nacodex server, cloud session, or local run on our workstation) is named on its page
  • Findings then re-checked by hand against the code at that commit and, where the lookup could run, compared with the project's public issues
  • Documentation re-checks compare the current published text with our earlier report
Fair use and corrections

Project and company names and their code belong to their owners and are used here only to identify what was audited. None of them has endorsed or reviewed these pages. If you maintain one of these projects and think something here is wrong, write to support@nacodex.help: we correct errors promptly and say so on the page.

Want this for your code?

Upload a ZIP or link a public GitHub repo, pick the areas and the depth, and get findings by severity with fixes.